Skip to main content

Industries

Cyber security for banking & finance.

Core banking, payments and card networks, audited against the frameworks your regulator actually inspects.

Regulators and frameworks

  • RBI
  • PCI DSS
  • NPCI
  • SWIFT
Talk to a banking specialist

What is actually going on here

Banking security in India is not one problem. It is a core banking system that cannot go down, a payments estate that changes every quarter as NPCI ships new rails, and a supervisory relationship where the Reserve Bank can ask for evidence at short notice. Most banks handle each of those with a different team, and the gaps show up in between them.

What we see most often is not a weak perimeter. It is a well defended bank with an unmonitored path between the internet facing channel and the switch, usually created by an integration that was tested for function and never for abuse. That is the path that matters, and it rarely appears on a network diagram.

We test the way an attacker with patience and a stolen customer credential would, then we sit with your team and prove the finding on your own systems. If it cannot be reproduced in front of you it does not go in the report.

Who regulates you, and what they want

Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.

Pick one or more above to see what they expect of you.

What goes wrong in this sector

  • Core banking and switch compromise

    The switch is usually the least changed and least tested system in the bank, which makes it the most attractive. Attacks come through a trusted integration or a vendor maintenance path rather than the front door. The damage is measured in minutes because settlement does not wait.

  • UPI and wallet fraud at scale

    Individual UPI fraud is a customer problem. Fraud that exploits a flaw in your collect flow, mandate handling or refund path is a bank problem, and it scales the moment somebody scripts it. We test the money movement logic, not just the login.

  • ATM and card network jackpotting

    Physical access plus an unpatched dispenser controller still works. So does a compromised ATM management network. Both are testable, and both are things a regulator will ask whether you have tested.

  • Insider access to customer records

    The most common real breach we investigate in banking is not an intrusion. It is a member of staff with more access than the role needs, exporting data over months. Access reviews catch this. Most access reviews are performed on paper.

How we work in this sector

  1. 01

    Map the money

    Before any testing we trace how value actually moves: channels, switch, core, settlement and the integrations between them. Almost every serious finding we have reported in banking sat on one of those seams.

  2. 02

    Test the path, not the asset

    We chain findings rather than listing them. A medium severity flaw in the customer channel plus a trust relationship into the switch is a critical, and we report it as one issue with one story.

  3. 03

    Prove it with your team watching

    Every finding is reproduced live for your engineers. This is where disputes get settled, and it is why our reports rarely come back contested.

  4. 04

    Stay until it is closed

    Re-testing is included. We do not consider the engagement finished when the report is delivered, because a report is not a fix.

What we actually keep finding here

Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.

  • Most engagements

    A trusted path from the customer channel to the switch

    Created by an integration that was tested for function and never for abuse. It rarely appears on the network diagram, and it is the single highest impact finding we report in banking.

  • Almost every engagement

    Access reviews performed on paper

    The policy says quarterly. The evidence shows a spreadsheet circulated once, partially returned, and never reconciled against what the directory actually says.

  • Often

    UPI flows tested for function, not for abuse

    Collect requests, mandate handling and refund paths that behave correctly for a well-intentioned user and can be driven somewhere else by an attacker with a script.

  • Most engagements

    Vendor maintenance access that outlived the project

    A permanent route in, with shared credentials and no logging, set up for an implementation that finished years ago.

Questions worth asking any provider in this sector

Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.

  1. 1

    Will you test the payment flow logic, or only the login and the perimeter?

  2. 2

    Are you CERT-In empanelled, and will the report be in the format an RBI inspection expects?

  3. 3

    Will you chain findings into an attack path, or hand me a list sorted by CVSS?

  4. 4

    Who specifically will do the testing, and will they be on the call when we walk through findings?

  5. 5

    Is re-testing included, and will you evidence closure rather than accept our word for it?

What we deliver in this sector

  • Core banking & payment system security testing
  • Mobile banking & wallet security assessment
  • ATM, POS & card network testing
  • Transaction fraud risk assessment
  • RBI & PCI DSS compliance testing
  • API security & identity access review
  • Cloud & infrastructure hardening
  • Continuous monitoring & threat hunting

Proof

Cyber security testing for Union Bank of Nigeria

Work in this sector

Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.

  • Banking

    Cyber security testing for Union Bank of Nigeria

    Cross-border security testing programme across core banking and customer-facing channels.

    International engagement

  • Client withheld

    Private sector bank, digital channel review

    Scope
    Mobile and internet banking plus the integration layer into core, ahead of a supervisory review.
    What we found
    A trusted path from the customer channel into the switch, reachable after a single stolen customer credential.
    Outcome
    Path closed, monitoring added at the boundary, and the finding chain used as the bank's own tabletop scenario.
  • Client withheld

    NBFC, payments and collections platform

    Scope
    UPI collect flows, mandate handling and the refund path, tested for abuse rather than for function.
    What we found
    A refund flow that could be replayed, and mandate handling that did not re-verify the payer on modification.
    Outcome
    Both fixed before launch of a new collections product, with re-testing to evidence closure.
All case studies

Questions we get asked in this sector

Can you test without touching production?

For most things yes, and we prefer it. But a UAT environment that differs from production in its integrations will hide exactly the findings that matter. Where that is the case we say so and agree a narrow, supervised production window rather than pretending the UAT result is equivalent.

Will the report be accepted by our RBI inspection?

We are CERT-In empanelled and our reports are written to the format supervisory reviews expect, including the closure tracking. What we cannot do is promise how a particular inspecting officer will read it. We can tell you what has been accepted before.

How long does a full banking assessment take?

For a mid sized bank, four to seven weeks depending on how many channels and how much of the estate is in scope. The variable is almost never the testing. It is how long access and environment provisioning takes on your side.

Do you work with our existing SOC?

Yes, and we would rather you kept it. If you have a SOC we run purple team style, telling them what we did and when, so you find out what their detection actually catches. That is usually more valuable than a stealth test.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.